PPN 014: Cyber essentials scheme · first published 17 February 2025
Procurement Policy Note (PPN) 014 updates the long-standing government requirement for suppliers to hold Cyber Essentials (CE) or Cyber Essentials Plus (CE+) certification on certain public contracts. It replaces two earlier notes (PPN 09/14 and PPN 09/23) and aligns language with the Procurement Act 2023, which applies to procurements started on or after 24 February 2025. The rule targets contracts where suppliers handle citizens' or government employees' personal data, run IT systems at OFFICIAL classification, or deal with day-to-day government business information. Certification must be in place before data is handed over and must be renewed every 12 months. Importantly, buyers must not apply the requirement as a blanket rule — it should only be asked for where genuinely relevant and proportionate, with explicit protections against over-burdening SMEs (Small and Medium-Sized Enterprises) and VCSEs (Voluntary, Community and Social Enterprises).
WHO THIS APPLIES TO
THE ENKII VIEW
The explicit instruction that buyers must not take a blanket approach and must avoid deterring SMEs is a meaningful protection — if a buyer demands CE certification on a contract where it is not relevant, you have grounds to challenge it. For SMEs already holding CE certification, this PPN is a competitive asset: you clear a mandatory gate that unqualified rivals cannot pass. The annual renewal requirement and the £300–£500+ cost are manageable for most small firms and should be treated as a standard cost of doing business with central government on data-touching contracts.
1. Obtain Cyber Essentials certification before bidding — budget £300–£500+ VAT, allow time for the questionnaire and independent verification, and diarise annual renewal.
SMEs bidding for any central government or NHS contract involving personal data or official IT systems — CE certification is a mandatory gate: 'evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier.' Without it, you cannot be awarded the contract.
2. Do not assume ISO 27001 satisfies the CE requirement — check whether all five CE technical controls are covered and obtain CE certification (or documented equivalent evidence) separately.
SMEs already holding ISO 27001 certification — The PPN explicitly states 'companies that attain this standard will not automatically conform to Cyber Essentials' because ISO 27001 typically does not cover all five CE technical controls.
3. Commission an independent, technically competent third party to verify your CE+ equivalent controls — self-assessment is not accepted for CE+ equivalence.
SMEs bidding for contracts requiring Cyber Essentials Plus (CE+) — 'To demonstrate that Cyber Essentials Plus requirements have been met, it is required in all cases that verification is provided by a technically competent and independent third party.'
4. Check your prime contractor's Model Services Contract — it will require you as a subcontractor to hold CE or CE+ (or equivalent), so obtain certification before the subcontract is signed.
SMEs who are subcontractors on large government services contracts over £20m — The Model Services Contract 'requires that the supplier and relevant subcontractors have Cyber Essentials or Cyber Essentials Plus certifications (or equivalent)' on complex services contracts exceeding £20m.
5. If CE is demanded but the contract does not involve personal data or official IT systems, formally question the buyer — the PPN explicitly prohibits blanket application and requires proportionality to protect SMEs from unnecessary burden.
SMEs who receive a tender requiring CE certification — 'In-scope organisations must not take a blanket approach... It is important not to over-burden suppliers or deter Small and Medium-Sized Enterprises (SMEs).' You have policy backing to challenge disproportionate requirements.
6. Voluntarily state your CE or CE+ status in your G-Cloud service listing — buyers are instructed to assure themselves of cyber risk management before awarding call-off contracts, so visible certification strengthens your position.
SMEs selling cloud services on the G-Cloud framework — 'Suppliers are encouraged to state if they have Cyber Essentials or Cyber Essentials Plus certification as part of their service offer' and buyers 'should assure themselves that the supplier(s) are managing relevant cyber risks effectively before making a contract award.'
7. Set a calendar reminder to renew CE certification every 12 months and track expiry dates against active contract durations — an expired certificate renders you uncertified mid-contract.
All SMEs bidding central government or NHS work — 'Suppliers must recertify every 12 months in order to maintain a valid certificate. Failure to do so renders the supplier uncertified.'
Every rule below quotes the official document verbatim.
Suppliers on certain contracts must hold Cyber Essentials or Cyber Essentials Plus certification, or demonstrate equivalent controls, before data is passed to them. (All in-scope contracts meeting the higher-risk characteristics; central government departments, executive agencies, NDPBs and NHS bodies from 24 February 2025.)
“evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier.”
This PPN applies to procurements commenced on or after 24 February 2025; earlier procurements remain under PPN 09/23. (Central government departments, executive agencies, NDPBs and NHS bodies.)
“The Procurement Act 2023 and the Procurement Regulations 2024 applies to procurements commenced on or after 24 February 2025.”
The PPN applies to central government departments, their executive agencies, non-departmental public bodies, and NHS bodies; other public sector bodies are encouraged but not required to follow it. (Central government and NHS bodies as mandatory; wider public sector as encouraged.)
“This PPN applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. Such bodies are referred to as 'in-scope organisations'.”
CE/CE+ is required on contracts where: citizens' or government employees' personal data is handled; IT systems storing or processing OFFICIAL-classified data are supplied; or contracts deal with day-to-day government business, service delivery, public finances, criminal justice, defence or commercial interests. (In-scope organisations; all sectors and contract values where these characteristics are present.)
“In-scope organisations must ensure that all suppliers demonstrate that they meet certain technical requirements for contracts or services that include the following characteristics: where personal information of citizens, such as home addresses, bank details, or payment information is handled by a supplier; where personal information of government employees, ministers and special advisors is handled by a supplier... where ICT systems and services are supplied which are designed to store, or process data at the OFFICIAL level of the Government Security Classifications Policy.”
Cyber Essentials certification must be renewed annually by the supplier for the duration of the contract. (Suppliers holding CE certification on in-scope contracts.)
“Where Cyber Essentials certification is required, it must be renewed annually by the supplier for the duration of the contract.”
The cost of Cyber Essentials basic certification for smaller companies is currently expected to be between £300 and £500 plus VAT. (SME suppliers seeking CE certification.)
“The cost for smaller companies to be Cyber Essentials certified is currently expected to range between £300 and £500+ VAT at basic level.”
ISO 27001 certification does not automatically satisfy Cyber Essentials requirements; firms holding ISO 27001 must still obtain CE certification or demonstrate equivalent controls. (All suppliers holding ISO 27001 who bid for in-scope contracts.)
“companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation.”
Suppliers may demonstrate equivalent controls in place of holding a CE certificate, but for CE+ equivalence must be verified by a technically competent and independent third party in all cases. (All suppliers on in-scope contracts where CE+ is required.)
“To demonstrate that Cyber Essentials Plus requirements have been met, it is required in all cases that verification is provided by a technically competent and independent third party.”
Buyers must not apply Cyber Essentials as a blanket requirement and must not over-burden SMEs or VCSEs. (In-scope buying organisations; relevant to SME and VCSE suppliers across all sectors.)
“In-scope organisations must not take a blanket approach... It is important not to over-burden suppliers or deter Small and Medium-Sized Enterprises (SMEs) and Voluntary, Community and Social Enterprises (VCSEs) from bidding for public contracts.”
The Model Services Contract for complex services contracts exceeding £20 million already requires suppliers and relevant subcontractors to hold CE or CE+ (or equivalent). (Suppliers and subcontractors on complex services contracts over £20m in value.)
“The Model Services Contract (MSC) is a standard contract used across government... particularly those with ICT and Business Process Outsourcing providers exceeding £20 million in value... This schedule requires that the supplier and relevant subcontractors have Cyber Essentials or Cyber Essentials Plus certifications (or equivalent).”
G-Cloud framework suppliers are encouraged to state CE/CE+ certification but it is not a mandatory requirement of the G-Cloud commercial agreement itself. (Suppliers on Crown Commercial Service G-Cloud Commercial Agreements.)
“Suppliers are encouraged to state if they have Cyber Essentials or Cyber Essentials Plus certification as part of their service offer, but it is not a requirement of the commercial agreement for suppliers to hold this certification.”
CE certification requirements must be specified in the tender notice for any competitive tendering procedure, and ideally raised with suppliers during preliminary market engagement. (In-scope buying organisations; informs supplier preparation timelines.)
“Any applicable Cyber Essentials requirements must be specified in the tender notice for any competitive tendering procedure, and consideration should be given to highlighting any Cyber Essentials requirements in notices preceding the tender notice (if applicable) to provide suppliers with the longest possible time to seek certification.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.